Red Hat Security Advisory: OpenShift Container Platform 4.18.48 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-26996 — minimatch: minimatch: Denial of Service via specially crafted glob patterns CVE-2026-33186 — google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:0af1c7e9b224f18d4d51ed6d8ea9aa9cb0f7dd4f15e0b6f0d7cf52ea686e068a_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:6c94c55b97b5a009a267cfbfa6ab123d1ebcb46df92bcf766c00a7f9e4346897_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:affefb0adef8b4551a9b9a0640e4739b0d585637ef31aa226b703ce285220ae2_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:bde191fc76af6e2ea2be80b0d98df3da5a6a1126c4a3e4b789e07382562def38_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:2fb414e1265c978155403f80bcab504354f61b9254eeaf2c9164cca2eb6c53af_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:818fce5c9833e01a9973fff295842f45b94502f349a3a0c29744761135bdaf1b_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:82bf26cae153eaeabc2cb972e30abce0388c5b22f55d2a3dacc8f9fb36101353_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:9cc943e96a18385db08b90f7bc869639f2d86ef31e208432f7579d48c5c684fb_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:a155f50ac245666bfe14f1876ff889a5f21a4faae50c6602edbc1ea8e9c43b29_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:bb7452af42a81e3b232d2531c9d1b3303604706aecafbf0a56c6a6d4ecf0bd02_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:c9e646025744e4a8d31173ce5dc9ebfd365337687bd1ce8c24e0b609c673d799_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:cc5f38244248cd05adc706d72c64724669319b28d152dec348aecc570fcf17f7_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:39c622e3af5ea07a60b7ae23a0a46f3aba0faaafce4c4246e86a6905abd94775_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:3ed347379f280ed14fe9508e6b0af4c991a30e7743a49cabbe0d7fa089c12f3a_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:5d43e19034b9b1334148e84df056f0984e6a86fcef16529c27123ea6ed8d1f4e_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/cloud-network-config-controller-rhel9@sha256:74653f2f728638910e52f35ef1b4668d2d0d40c13ce6f9151b830c5906c9b35d_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:38466ba2ee2fe334f8f38ac644cb265e93c8c2303d476e15ae4eed6cc2047da7_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:61c5b33d1f0a81482d2673e51e4c47d50b8a504ba2955b50107549bc3b013627_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:95f275c6810fef237c3451be961d92540b456879274e1dd7c5f09ac8d7ae5b86_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/container-networking-plugins-microshift-rhel9@sha256:dbca4abd08dc574acbf8d769294fbf35daab49d2aad34eb2d24144bef7898f65_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:4e97e51f0e3eed3a9815df5ffd0099652f3af4f854e4325b24fd5f78a1c1dee5_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:92c70ce0eee30c5effccf1378fa0b896bb095d94ba3ca4db386aff0f5aee8b39_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:ae4caa149c620ff4813de444bb32598632dbaadfe9dd63ed742ddf047e02f5a4_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/driver-toolkit-rhel9@sha256:d4ec93ede55d8d915dfd6406b3f1b4b8b6355a1c68e87756b88fc5b1e32929d9_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:0b61d55e4fc6f2d621b730cee02f8bb1942e6bd34e1ac6e2bc5c81fb786f4a47_ppc64le as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:538a1438be0524b7bd26440128e0698e09fc14f0512487a5346b39ede02bd502_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:8b4dfaa612d63cb85c1f99a56633bf967f59b7c1090c7620a851ba6ca6fce9f2_s390x as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/egress-router-cni-rhel9@sha256:b12e2bc526c059191e0ec0801182712814f40b77c9fa578d9aeef7606564a1e8_arm64 as a component of Red Hat OpenShift Container Platform 4.18
- registry.redhat.io/openshift4/frr-rhel9@sha256:1a49f76f67249a25714636ea36167945efbc18b15640a366786aaf20bfc779e7_amd64 as a component of Red Hat OpenShift Container Platform 4.18
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:186541b2694432bda8df7e572ad0d4b97031b10295394afaa496821e10b51663 (For s390x architecture) The image digest is sha256:9e79fbe9868f1367fe412d7a2e6fcf1267e170c7cbc1d9341e81240aa113da12 (For ppc64le architecture) The image digest is sha256:ffbef6ee94ccd816deca19c331e4658d148312cdaafcd5d14f12cd9e0c0da1fa (For aarch64 architecture) The image digest is sha256:e336bbfa0913a24a66ec7fb4e5fcf730ef9ccd5a389a0298a80610cfdcc34d1c All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. Workaround: To mitigate this issue, implement infrastructure-level normalization to ensure all incoming HTTP/2 `:path` headers are properly formatted with a leading slash before reaching the gRPC-Go server. This can be achieved by configuring a reverse proxy or API gateway to validate and normalize the `:path` header. Ensure that any such intermediary is properly configured and restarted to apply the changes, which may temporarily impact service availability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:37192
- externalhttps://access.redhat.com/security/cve/CVE-2026-26996
- externalhttps://access.redhat.com/security/cve/CVE-2026-33186
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_37192.json